Skip to content
Critical Command Injection Vulnerability in Tenable Identity Exposure SaaS

Critical Command Injection Vulnerability in Tenable Identity Exposure SaaS

First seen 9 Oct 2026, 04:33 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 9, 2026 at 05:33 UTC
  • •CVE-2026-106126 has a CVSS score of 9.9, indicating critical severity.
  • •The vulnerability allows low-privileged attackers to execute commands on the PDCe.
  • •Immediate upgrade to TIE SaaS version 3.126.0 is required for remediation.

A critical command injection vulnerability (CVE-2026-106126) has been identified in the Tenable Identity Exposure SaaS platform, rated 9.9 on the CVSS scale. This flaw allows authenticated, low-privileged attackers to execute arbitrary commands with SYSTEM-level privileges on the Primary Domain Controller Emulator (PDCe), potentially compromising the entire domain. The vulnerability resides in the Active Directory Events Listener, which is responsible for collecting security event logs. Organizations are urged to upgrade to TIE SaaS version 3.126.0, released on October 8, 2026, and follow specific remediation steps to mitigate the risk. As of the advisory, there is no evidence of active exploitation or public exploit code. This incident reflects a concerning trend of vulnerabilities targeting identity infrastructure components, similar to recent issues with HPE ClearPass and Cisco products.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-03-04
CVE-2026-20131 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-16
CVE-2026-76460 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-30
CVE-2026-102489 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-08
Patch released for Tenable Identity Exposure
Tenable released TIE SaaS version 3.126.0 to address the critical command injection vulnerability.
Tech.Yahoo
2026-10-08
CVE-2026-106126 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-09
Vulnerability disclosed
The critical command injection vulnerability (CVE-2026-106126) was publicly disclosed, prompting immediate attention from security teams.
Tech.Yahoo

More articles in this cluster (2)

Following this threat?

Track CVE-2026-102489 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What systems are affected by CVE-2026-106126?
The vulnerability affects the Tenable Identity Exposure SaaS platform, specifically the Active Directory Events Listener.
Is there any evidence of exploitation in the wild?
As of the latest advisory, there is no evidence of active exploitation or public exploit code.
What should organizations do to mitigate this vulnerability?
Organizations must upgrade to TIE SaaS version 3.126.0 and follow the remediation steps outlined in the advisory.